SV-21811r3_rule
V-19670
VVoIP 6325
VVoIP 6325
CAT II
10
Ensure the DISN NIPRNet IPVS SBC is configured to drop the following signaling packets:
- SIP packets arriving on IP port 5060 or 5061
- SIP packets arriving on IP port 443 not secured with TLS
- AS-SIP packets arriving on IP port 5060
- AS-SIP packets arriving on IP port 5061 not secured with TLS
NOTE: The VVoIP system may allow SIP and SRTP traffic encrypted and encapsulated on port 443 from Cloud Service Providers.
Interview the ISSO to confirm compliance with the following requirement:
Ensure the DISN NIPRNet IPVS SBC is configured to drop the following signaling packets:
- SIP packets arriving on IP port 5060 or 5061
- SIP packets arriving on IP port 443 not secured with TLS
- AS-SIP packets arriving on IP port 5060
- AS-SIP packets arriving on IP port 5061 not secured with TLS
If all SIP and AS-SIP packets are not dropped except AS-SIP packets secured with TLS arriving on IP Port 5061 and SIP packets secured with TLS arriving on IP Port 443 secured with TLS, this is a finding.
NOTE: The VVoIP system may allow SIP and SRTP traffic encrypted and encapsulated on port 443 from Cloud Service Providers.
V-19670
False
VVoIP 6325
Interview the ISSO to confirm compliance with the following requirement:
Ensure the DISN NIPRNet IPVS SBC is configured to drop the following signaling packets:
- SIP packets arriving on IP port 5060 or 5061
- SIP packets arriving on IP port 443 not secured with TLS
- AS-SIP packets arriving on IP port 5060
- AS-SIP packets arriving on IP port 5061 not secured with TLS
If all SIP and AS-SIP packets are not dropped except AS-SIP packets secured with TLS arriving on IP Port 5061 and SIP packets secured with TLS arriving on IP Port 443 secured with TLS, this is a finding.
NOTE: The VVoIP system may allow SIP and SRTP traffic encrypted and encapsulated on port 443 from Cloud Service Providers.
M
3407